SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Information Architecture

Perfect authentication remains elusive

Perfect authentication remains elusive

By:  Bill Brenner  On: 03 Mar 2010 For: CSO (US) 

Users pick easy-to-crack passwords like the name of a dog or a favourite movie, but multi-factor authentication may end the insanity

For years, leaders of the security industry have warned that passwords have outlived their usefulness. Users pick easy-to-crack passwords like the name of a dog or a favourite movie. They're written on post-it notes and left sticking to the monitor for all to see. 

Multi-factor authentication -- using more than one form of authentication to verify the legitimacy of a transaction via smart cards, tokens or biometrics, for example -- is often held up as the alternative; an end to insanity.

The reality is far less simple.

At Security B-Sides Tuesday, a panel discussed the best ways to address the problem.

Marisa Fagan, security project manager at Errata Security, mapped out the problem security shops face. Errata, she said, has found that 10 percent of all Twitter traffic is comprised of phishing and malware attacks. Many users are often duped into clicking on a phishing link or their password is so easy to guess that the bad guys crack it. From there, the path to one's sensitive data is shorter and clearer.

"Recycled passwords are a problem," she said. Launch a brute-force attack and access a password and you're in business. Cracked Facebook passwords are being sold for $100 or less, she noted.

"There are different ways to solve the authentication problem, but removing passwords would kill all the birds with one stone," Fagan said. "The question is how best to go about it."

Multi-factor authentication would seem the easy answer. But here's the problem: Attackers can also get around that with little trouble. The reason, as in the password problem, is that users end up being the path of least resistance.

"People will write their PINs right on their token. So have we decreased risk? We've created a bigger barrier" but that's not enough, said Michael Santarcangelo, founder of the Security Catalyst Community.

Jennifer Jabbusch, CISO at Carolina Advanced Digital Inc. in North Carolina, noted how companies implement multi-factor authentication but don't always get the implementation right. That's when the company is left with nothing but "feel-good security."

"We need to draw a line and not pursue solutions that simply offer a feeling of security," she said. "Things make you feel better don't really help."


Sign up for our Newsletters












Print |  Views: 1534   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




bill brenner Bill Brenner is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Streamlined authentication system cuts costs
Streamlined authentication system cuts costsCanadian businesses with remote workers and confidential Web sites may benefit from CRYPTOCard’s new 2FA system. CEO explains how BlackShield ID reduces admin and management tasks by 90 per cent.
Phishers beat banks' strong authentication
Phishers beat banks' strong authenticationScammers have found a way around new token-based authentication systems that have been adopted by some banks
The games hackers play
The games hackers play This clash has nothing to do with the simulated battles on Gindis, Eternal Duel, Mobstar or any of the more hip gaming sites. No, this one's for real. The villains in this combat are criminal hackers and phishing scammers, and their targets: unsuspecting online gamers.
BlackHat USA 2008 - Day 2 Review
today was the second and final day of the blackhat usa briefings. a lot of great content was presented today. much like yesterday we’ve included some highlevel comments on the various presentations that tadd and i attended. we will be attending defcon over the weekend and tying that into one final posting next week. what follows is our summary.

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.